You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用AWS CDK配置Cognito用户池授权码流遇身份提供者未启用问题

解决AWS CDK创建Cognito OAuth授权码流时身份提供者未启用的问题

这不是bug,也不是模块处于实验阶段的问题——只是你在配置User Pool Client时,需要显式指定要启用的身份提供者。虽然手动在Cognito控制台创建客户端时会默认勾选自身作为身份提供者,但CDK为了保持配置灵活性,不会自动帮你添加该设置,除非你明确声明。

你只需要两步修改就能解决:

  1. 导入UserPoolClientIdentityProvider枚举
  2. 在addClient的配置里添加identityProviders属性,指定启用Cognito User Pool作为身份提供者

修改后的完整代码如下:

import * as cdk from '@aws-cdk/core';
import { UserPool, VerificationEmailStyle, OAuthScope, UserPoolClientIdentityProvider } from '@aws-cdk/aws-cognito'; // 新增枚举导入
import { Duration } from '@aws-cdk/core';

export class UserPoolStack extends cdk.Stack {
  constructor(scope: cdk.Construct, id: string, props?: cdk.StackProps) {
    super(scope, id, props);

    const userPool = new UserPool(this, 'stackoverflow-userpool', {
      userPoolName: 'stackoverflow-userpool',
      selfSignUpEnabled: true,
      signInCaseSensitive: false,
      userVerification: {
        emailSubject: 'Verify your email!',
        emailBody: 'Hello, Thanks for signing up! {##Verify Email##}',
        emailStyle: VerificationEmailStyle.LINK
      },
      signInAliases: {
        username: true,
        email: true
      },
      requiredAttributes: {
        email: true
      },
      passwordPolicy: {
        minLength: 12,
        requireLowercase: true,
        requireUppercase: true,
        requireDigits: true,
        requireSymbols: true,
        tempPasswordValidity: Duration.days(7)
      }
    });

    const client = userPool.addClient('stackoverflow-userpool-localhost-client', {
      userPoolClientName: 'stackoverflow-localhost-client',
      oAuth: {
        flows: {
          authorizationCodeGrant: true
        },
        scopes: [OAuthScope.OPENID],
        callbackUrls: ['http://localhost:4200/callback']
      },
      // 新增配置:显式启用Cognito User Pool作为身份提供者
      identityProviders: [UserPoolClientIdentityProvider.COGNITO]
    });

    userPool.addDomain('stackoverflow-userpool-domain-prefix', {
      cognitoDomain: {
        domainPrefix: 'stackoverflow'
      }
    });
  }
}

部署修改后的栈之后,再去Cognito控制台查看App Client的身份提供者设置,就能看到Cognito User Pool已经被启用,授权码流也能正常工作了。如果你的CDK模块版本较旧,建议升级到稳定版(比如v1.x或v2.x的正式版),避免一些已知的配置兼容性问题。

内容的提问来源于stack exchange,提问作者Shamshiel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 19:03:13